koraycodes[verified]@koraycodesPatch
The update to libexpat 2.7.4 includes patches for CVE-2026-24515 and CVE-2026-25210, mitigating memory amplification and XML parsing crashes, while also neutralizing a critical use‑after‑free bug in the ssl module.
ThreatCluster[verified]@threatclusterDisclosure
The tweet announces Expat XML parser vulnerabilities (CVE‑2025‑59375, CVE‑2026‑24515, CVE‑2026‑25210) affecting Ubuntu, noting DoS and potential code execution via crafted XML, without providing PoC, exploit, or patch details.
Open Source Security mailing list@oss_securityPatch
The post announces that libexpat version 2.7.4 includes a patch fixing CVE-2026-24515 (NULL pointer dereference) and CVE-2026-25210 (Integer overflow) with no evidence of active exploitation or PoC.
Security Bug Aggregator@BugsAggregatorDisclosure
The post announces CVE‑2026‑25210 affecting Chromium source and links to a Crbug issue, but provides no further technical detail, PoC, or exploit information.
Ferramentas Linux@Cezar_H_LinuxPatch
The tweet announces that SUSE Linux Micro 6.1 has released patches addressing CVE-2026-24515 (NULL dereference) and CVE-2026-25210 (integer overflow).
Lambda Watchdog@LambdaWatchdogPatch
AWS Lambda base images have been updated to remove CVE-2026-25210, indicating the vulnerability has been patched.
Lambda Watchdog@LambdaWatchdogDisclosure
The tweet announces a new Medium‑severity CVE (CVE‑2026‑25210) that affects expat in several AWS Lambda base images, with links for more details.
Ferramentas Linux@Cezar_H_LinuxPatch
The Ubuntu Security Notice announces CVE-2026-25210 as a potential RCE via an integer overflow and indicates that patches are available only in Ubuntu Pro/ESM repositories.